The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Neutron | Openstack | 2013.1 (including) | 2013.2.3 (including) |
OpenStack 4 for RHEL 6 | RedHat | openstack-neutron-0:2013.2.3-7.el6ost | * |
Neutron | Ubuntu | devel | * |
Neutron | Ubuntu | saucy | * |
Neutron | Ubuntu | trusty | * |